Enterprise Procurement FAQ
The questions enterprise procurement, legal, and information security teams ask most often about the RynIQ™ Platform — answered in one document, cross-linked to the primary sources in this pack.
| Version | 1.0 | Effective | On publication |
|---|---|---|---|
| Supersedes | — | Governing law | Estonia · EU |
Where is customer data stored?
The RynIQ™ Platform is EU-hosted by default via our managed database and hosting subprocessors listed in the Subprocessor List. US regions are available on request for customers with a documented residency requirement. Backups reside in the same region as primary storage.
How is AI used inside the product?
Models assist analysis: they cluster, structure, and summarise the responses executives provide. No decision that produces legal or similarly significant effects is taken solely by automated means. Every Executive Decision Brief is reviewed by a human before delivery. Full detail is in the AI Transparency Statement and the Responsible AI Policy.
Do you use customer data to train AI models?
No. Ryniqo does not use customer Executive Reviews, Snapshots, workshop content, or any other customer input to train, fine-tune, or otherwise improve public or third-party AI models. This is enforced by contract with our model providers, which apply zero-retention or short-retention terms.
Can customers export or delete their data?
Yes. Customers can export every answer, initiative, and generated brief associated with their organisation in JSON + PDF form. Deletion is honoured within a defined SLA (currently 30 days) except where retention is required by law. See the Privacy Policy and the DPA.
How do you handle subprocessors?
The Subprocessor List documents every current subprocessor, its role, and its processing location. Customers are notified in advance of any material change with a right to object. Every subprocessor is contractually bound to data-handling standards that flow down from the DPA.
How do you respond to security incidents?
Detection and response are covered in the Information Security Policy. Confirmed incidents affecting customer personal data are notified without undue delay in line with Article 33 GDPR and the DPA. Communications include scope, containment, root cause, and remediation.
How do individuals exercise GDPR rights?
Rights requests (access, rectification, erasure, restriction, portability, objection) go to privacy@ryniqo.com and are answered within one calendar month, extendable by two further months for complex requests under Article 12(3) GDPR.
Are you certified against SOC 2 or ISO 27001?
Not today. We are aligned with the principles of ISO/IEC 27001:2022 and ISO/IEC 42001:2023, and SOC 2 Type II is on the roadmap. We do not claim certification we do not hold. See the Compliance Statement for the current, honest state.
Do you support a signed DPA?
Yes. A counter-signed copy of our Data Processing Agreement is available upon request for enterprise customers. We can also negotiate against a customer's own DPA using ours as the reference text.
Who owns the outputs of the Executive Decision Brief?
The customer. Ryniqo retains no commercial rights over the Brief or its content. Ryniqo may retain anonymised, aggregated learnings that cannot be traced back to a customer for the purpose of improving methodology, unless the contract states otherwise.